NEW YORK, New York – 31st July 2026 – Bright Security today announced updates to its STAR platform that connect dynamic application scanning, runtime validation, remediation guidance, and post-remediation checks within software development pipelines.
The update is intended to help development and security teams evaluate running web applications and APIs throughout the development lifecycle. STAR uses dynamic application security testing to interact with deployed applications and identify behavior that may expose an exploitable application-layer vulnerability.
Updated STAR Workflow
Bright Security identified the following areas of enhancement:
- Pipeline-based scanning: STAR can be configured to run against production-like application instances as part of build and deployment workflows.
- Runtime validation: Findings are checked against the running application to determine whether the associated behavior can be reproduced.
- Application and API coverage: Scans evaluate web interfaces, APIs, authentication flows, and supported business processes.
- Remediation support: Findings can include contextual guidance for development teams and can be routed through existing engineering workflows.
- Post-remediation checks: Relevant tests can be run again after a code change to confirm whether the observed runtime behavior has been addressed.
- Code-origin independence: The workflow evaluates application behavior regardless of whether the underlying code was written by a person or generated with an AI development tool.
The platform’s continuous DAST security capabilities complement code analysis by examining how an application responds while running. Bright Security said this runtime approach is intended to provide development teams with reproducible evidence and application context rather than relying solely on source-code indicators.
“The practical goal is to give development and security teams evidence they can reproduce before a release, then help them confirm that a correction changed the application’s runtime behavior,” said Gadi Bashvitz, chief executive officer of Bright Security. “That keeps the workflow centered on the running application and gives teams a clearer basis for prioritization.”
AI Application Security
The STAR update applies the same runtime testing process to applications containing human-authored or AI application security. This approach recognizes that code origin alone does not establish whether a vulnerability is reachable or exploitable in a deployed environment.
Bright Security is not publishing numerical performance claims or comparative benchmark results with this announcement. Outcomes may vary according to application architecture, scan configuration, authentication coverage, pipeline design, and the vulnerabilities under review.
Availability and Deployment Information
Bright Security announced the platform update on July 30, 2026. A general rollout schedule, edition-specific eligibility, pricing changes, and any additional deployment requirements were not detailed in this release. Current and prospective customers can request information relevant to their environments through Bright Security or by contacting support@brightsec.com.
About Bright Security Bright Security provides application security technology focused on dynamic testing of running web applications and APIs. Its STAR platform integrates scanning, runtime validation, remediation guidance, and post-remediation checks with development workflows. The platform is designed for continuous delivery environments and supports the evaluation of applications containing both human-authored and AI-generated code.
Media Contact
Media Relations
Bright Security
support@brightsec.com
https://brightsec.com/